SuperImager Plus Forensic 7 inch Mini - Field Forensic Imaging and Platform. The unit can be used as a Field Forensic Imaging device, Cellphone/Tablets data extractions and analysis, and Triage data collections.
The unit as Forensic Imager:
The SuperImager Plus 7 inch MiniM Forensic field unit is very small, lightweight, and easy to carry, and it is the perfect tool to perform Forensic Imaging out in the field. It built with 7" Touchscreen color LCD display, 3 SATA ports (with secure and keyed SATA power connector), 4 USB3.0 ports, 1Gigabit Ethernet, and VGA port. It is affordable, and capable of performing extremely fast Forensic Imaging (Run SHA-1 hash authentication @ 30GB/min with use of Solid State Drive (SSD), 10GB/min with use of 1TB WD Blue Hard Disk Drive).
The SuperImager application has the capabilities to perform in one read pass from the "Suspect" hard disk drive:
Forensic Imaging with E01 format and full compression, Encryption with AES256, 3 parallel hash authentication (MD5, SHA1, SHA2), a simple binary keyword search, and the ability of Saving Forensic Images to 2 external SATA Evidence Hard Disk Drives, External compact USB3.0/eSATA RAID encrypted storage device, and to a local Network.
With the use of 4 USB3.0 to SATA optional kit, user can covert 4 USB3.0 to SATA ports and use the SuperImager Plus 7 inch Mini Forensic Field unit with a total 7 SATA ports and perform forensic imaging of 2:5 (2 Suspect 5 Evidence).
As a Field Data Eraser unit:
User can erase hard disk drives and USB3.0 storage devices, by using the unit’s 2 SATA ports and 3 USB3.0 ports. The application supports DoD erase, Security Erase, Enhanced Security Erase protocols which are NIST 800-88 compliance.
As a field Forensic platform:
Forensic investigator can load and run third-party applications such as Cellebrite, Oxygen, BlackBag, Paraben, or a Triage data collection applications such as Nuix, Encase, MPE+, all of which is done with excellent performance.
Optional External Battery:
An External Compact Battery Option is available: User can complete Forensic Imaging of WD 1TB hard disk drives (1:2) for around 2 hours, or perform a cellphone extraction and analysis for around 5 hours.
Dual Boot Option:
User can purchase the unit with only Linux OS for Forensic Imaging purpose. Dual Boot to Windows is optional for additional cost.
For Data Capture Under Linux:
Perform Forensic Imaging under Linux for a faster, more efficient and a more secure operation.
To Analyze the Captured Data Under Windows:
Reboot the unit to Windows, and use third-party applications to perform data analysis and other tasks.
Network Multiple Forensic Images Loader:
Unique feature solves 1Gigabit/s Port Bottleneck. User can upload many Forensic images directly to a local network using 5 equivalent 1Gigabit/s network streams.
Compare Windows to Linux application with E01 format and full compression on a hard disk drive with 50% random data: Linux: E01 Non compressed average speed of 3.6GB/min, E01 compression average speed of 4.3GB/min. Windows application with the same data with E01 format compression average speed of 3.8GB/min, all runs were with SHA-1+MD5 hashing authentication enabled. The Linux application increased the speed over Windows by 13%.
- HPA/DCO Automatic Supports: The application has the ability to automatically open HPA and DCO areas, and resize the "Suspect" hard drive to its full native capacity, in order to capture any "hidden data" (HPA/DCO are special areas on the hard disk drive that support this feature).
- Bad Sectors Handling: User can select to skip bad sectors/blocks, or abort the operation when it encounters bad sectors/block of sectors on the "Suspect" hard disk drive
- Forensic Images Destination: User can save Forensic Images to a local network shared folder for easy access and analysis, or save images to external USB3.0 RAID (encryption is optional) storage in a very good speed.
- Captured Storage Protocols and Interfaces: SAS, SATA, e-SATA enclosures, IDE, USB2.0, USB3.0, MMC.
- Form Factors: Capture data from various form factor devices: 3.5", 2.5", ZIF, 1.8", Micro-SATA, Mini-SATA.
- Cross Copy from Ports and Interfaces: The user can choose to capture from one type of port, storage protocol and interface, and save the forensic Images into a different port, storage protocol and interface. The cross copy of data can be done between SATA/IDE/USB interfaces.
- GUI: The application is built with large icons and is very simple and easy-to-navigate. In a few clicks user can set the operation, and it will be quickly up and running.
- Speed: Extremely fast
- Tested with Hash verification operation with SHA-1 enabled the recorded top speed was 30GB/min with Solid State Drive, and 10GB/min with 1TB WD Blue SATA-3 Hard Disk Drive.
- Tested with Forensic Imaging operation of 1 to 2 with SHA-1 enabled the recorded sustained top speed was 29GB/min with 3 SSD of SanDisk 120GB Extreme II.
Main application Features:
- Forensic Imaging Mode.
- Forensic Restore back data to original.
- Erase data from drives and Quick Format.
- Hash calculation authentication and verification.
Main Forensic Imaging Mode Features:
- Forensic Imaging Mode 100%, DD, E01/Ex01 – with optional compression.
- Hash while capture: MD5, SHA-1, SHA-2 (all 3 can be selected simultaneously).
- Erase Reminder of the drive.
- Keyword search.
- Parallel Forensic Imaging - Multiple Session Operations: User can run a multiple efficient parallel operation, since many ports are available. User can mix different type of operations, and each operation is set as a new independent session. Example of operations: erase data from a hard disk drive on one port, hash verify on second port, while forensic imaging 1 to 1 on the remaining ports.
- Basic Parallel Forensic Imaging: The supported modes are:
- Native SATA: 1 to 1, 1 to 2
- USB3.0: 1 to 1, 1 to 2, 2 to 2 and up to 2:4
- More Ports for Forensic Imaging: With the use of USB3.0 to SATA fast adapters, the unit can support up to 2 to 5 of SATA Hard Disk Drives
Parallel operation – Linux Elaborated:
- Hard Drive Detection Application Screen: All hard disk drives and storage devices that are connected to the units will be scanned and displayed in one application screen called "the detection screen". User can tap on each drive to get its detailed info, as well as selecting it for the desired operation they are planning to use.
- Parallel Forensic Imaging: It depends on the number and the kind of ports that each model has. The application is very flexible in running multiple sources to multiple destinations, all in a simultaneous operations. The user has the flexibility to change a role of a port from Evidence to Suspect, and is not limited by the pre-assigned "Suspect" ports. The session control application screen provides the user with a very comprehensive information and control over the running sessions, including all the setting of the session, and ability to abort the session.
- Parallel Forensic Imaging - Multiple Session Operations: User can run multiple efficient parallel operations and can mix different type of operations; for example erase hard disk drive on one port, hash verification on another port, while performing forensic imaging on other ports (each operation can function as a new independent session). The number of sessions also depends on the CPU: i5 -4 sessions, i7- 8 sessions.
- Network Capture: Data from network folder can be captured and saved into "Evidence" drives via iSCSI storage protocols.
- Saves Forensic Images to the Network: Upload multiple Forensic images to a local network (DD, E01), simultaneously by using up to 5 parallel 1Gigabit/s network.
- Remote Capture - Capture Data from the Internal Hard Disk Drives of a Computer: Using USB or 1Gigabit Ethernet ports of the laptop/computer, enables capture without the needs to remove the hard drive from the laptop/computer (Speed is restricted to performance of the Laptop/PC CPU and the 1Gigabit/s connection).
Erase and Quick Format Operation:
- Hard Disk Drive Erase Protocols: DoD 5220-22M, Security Erase, Enhanced Security Erase, or user can define the final data filling pattern and the number of iterations (DoD and Security Erase protocols are NIST 800-88 compliance).
- Quick Format: NTFS, FAT, HFS+, EXT4, and exFAT.
- Logs and Erase Certification: The application generates extensive erase log files and erase certification (option to save to NIST 800-88 format) that are easy to export to USB flash drive.
Unit as a Platform:
- File Preview: Browse and preview captured data on the Internal Display.
- High Performances: As a platform, a forensic investigator can, in addition to imaging and capturing data, load and run third-party applications to analyze the captured data:
- Cellphone/Tablet data extraction and analysis: Cellebrite, Oxygen, BlackBag, MPE+, Paraben applications.
- Triage data collection: Nuix/Encase portable applications
Expansion capabilities and the main hardware options:
- USB3.0 to SATA adapters and Kits Option: Today USB3.0 technology is extremely fast and can run read data from SSD drives up to 20GB/min with the use of USB3.0 to SATA 4 channel kit, user can convert 4 USB3.0 ports to 4 SATA ports on any of MediaClone units. The optional Kit is supplied with one external PS, and it includes all the cabling to power and connected the 4 USB3.0 to SATA adapters. The tested performance when running 4 adapters in parallel was measured at a very high speed, with a very little speed degradation.
- USB3.0 to M.2 (NGFF) adapters Option: Currently, most laptops and tablets use M.2 (NGFF) Storage devices. This adapter supports connectivity to some of the newest SSD M.2 storage (Storage that is supported by SATA Protocols). There is a class of SSD drives with NGFF connectors, which are not supported by SATA protocols, and cannot be used with those adapters. Also the M.2 (NGFF) connectors use to comes in a variety of connectors and it was not standardized until 2014.
- USB3.0 to M.2 (NGFF) PCIE base Option: Supports SSD used in MacBook Air 2012+, MacBook Pro Retina 2012+
- External Battery Option: Support the use of external Lithium-Polymer battery that enable user to run a full data capture in the field on hard disk drives, operated on battery for a long time. (Able to complete forensic imaging of WD 1TB hard disk drives with imaging mode of 1 to 2 for 2 hours, or Cellphone data extraction and analysis for 5 hours, all preformed with the use of the external battery).
- Warranty: One year warranty for the main unit. (It is not include cables and accessories).